Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Download and install IBM Common Licensing 9.1 from Passport Advantage https://www.ibm.com/software/passportadvantage/pao-customer Users are strongly advised to update to the latest version (IBM Common Licensing 9.1) to mitigate any potential risks associated with these vulnerabilities.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286490 |
|
Fri, 18 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Title | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent | |
| First Time appeared |
Ibm
Ibm common Licensing |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:ibm:common_licensing:agent:*:*:*:*:*:*:* cpe:2.3:a:ibm:common_licensing:art:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm common Licensing |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T15:38:37.630Z
Reserved: 2025-12-31T14:56:30.484Z
Link: CVE-2025-15399
No data.
Status : Received
Published: 2026-09-18T16:17:02.387
Modified: 2026-09-18T16:17:02.387
Link: CVE-2025-15399
No data.
OpenCVE Enrichment
No data.
-
CWE-352
Cross-Site Request Forgery (CSRF)